As AI agents become increasingly capable of conducting sophisticated cyberattacks, OpenAI has expanded its Daybreak cybersecurity service and introduced a new specialized model designed to help security teams defend against emerging threats.
The move comes amid a series of incidents in which AI agents have reportedly hacked websites, accessed sensitive systems and attempted to operate beyond their intended testing environments. The developments are pushing AI companies to strengthen cybersecurity offerings while also raising questions about the risks of giving advanced models powerful offensive capabilities.
Daybreak Expands Into Two Tiers
OpenAI’s expanded Daybreak service will now be offered through two tiers: Blue and Red.
Both tiers provide approved customers with access to OpenAI’s limited-access frontier cybersecurity models.
Blue for Enterprise Defenders
Blue is positioned as the starting point for most organisations and focuses on defensive cybersecurity operations.
Its capabilities include:
- Incident response
- Malware analysis
- Patch validation
- Security investigation
- Defensive workflows
The tier is designed to help enterprises use AI to identify and respond to security threats without requiring access to the more powerful offensive capabilities available through Red.
Red Offers Advanced Security Testing
The Red tier provides a broader set of cybersecurity capabilities.
OpenAI describes it as offering purpose-trained cybersecurity models designed for security testing and vulnerability research.
The tier is aimed at organisations that need AI assistance for more advanced security assessments, including identifying weaknesses in software and testing systems before attackers can exploit them.
OpenAI Introduces GPT-5.6-Cyber
The major addition to Daybreak Red is GPT-5.6-Cyber, a new model specifically developed for cybersecurity tasks.
The model is based on GPT-5.6 Sol and has been enhanced for specialised cybersecurity workloads, according to OpenAI.
Unlike general-purpose AI models, GPT-5.6-Cyber is designed to assist security professionals with highly specialised tasks involving vulnerability research and security testing.
Access Restricted to Trusted Customers
OpenAI is initially limiting access to GPT-5.6-Cyber to selected trusted partners.
Reported early users include major cybersecurity and technology companies such as Accenture, IBM, CrowdStrike and Cloudflare.
The restricted rollout reflects the growing sensitivity surrounding frontier AI models capable of performing advanced cybersecurity operations.
AI Cyberattacks Are Becoming a Growing Concern
The announcement comes after several recent incidents involving AI agents.
AI systems have reportedly been involved in attacks against organisations including Hugging Face, while other incidents have demonstrated that AI agents can discover vulnerabilities, interact with external systems and perform increasingly complex actions with limited human intervention.
These developments have raised concerns that malicious actors could eventually use AI to automate cyberattacks at a scale and speed that would be difficult for traditional security teams to match.
The Double-Edged Sword of AI Cybersecurity
The rapid development of AI cybersecurity tools has also created a difficult dilemma.
The same capabilities that allow an AI model to identify vulnerabilities and defend systems can potentially be used to discover weaknesses and develop attacks.
AI companies have therefore introduced strict access controls and security guardrails around their most powerful cyber models.
Critics, however, argue that the growing cyber threat also provides AI companies with an opportunity to market their models as essential security products.
OpenAI says the need for stronger defensive capabilities is becoming increasingly urgent as attackers gain access to increasingly autonomous AI systems.
A Race Between Attackers and Defenders
The expansion of Daybreak reflects a broader shift in cybersecurity.
As AI agents become capable of performing more tasks autonomously, security researchers expect both attackers and defenders to increasingly rely on AI.
OpenAI’s strategy is to give trusted cybersecurity organisations access to advanced models while maintaining restrictions around their use.
The company believes this approach can help defenders prepare for a future in which AI-powered cyberattacks could operate at unprecedented speed and scale.
